Sign inSign up
FRRouting

dhi.io/frr

FRRouting 10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips-dev, 10-debian13-fips-dev, 10-fips-dev, 10.7-debian-fips-dev, 10.7-debian13-fips-dev, 10.7-fips-dev, 10.7.1-debian-fips-dev, 10.7.1-debian13-fips-dev, 10.7.1-fips-dev

Index digest:

sha256:269aca8356a807c110c10260f0938e3907f8c5bfbf81a710cde7542195b21bd9

Manifest digest:

sha256:fe1aa17c2a3a483734f49e638543a972bdf450ce4e978d1f23a8a5b28e595575

Size

83.21 MB

Last pushed

16 hours ago

Vulnerabilities

0
2
4
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/frr:10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/frr:10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/frr@sha256:b671350f587486697abf869cb111eb137a375aa1cb6129377f6b7333678ed3d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/frr@sha256:e5ceb4a00f78f2ee5da282a3d37dd2bc17b3d5149d5d10912a46e689470ca850
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/frr@sha256:9102912c96de8616bca6b8fa51392cfa5f6839116befeaf1f67a40d80fe63999
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/frr@sha256:c8a63e5a38900c5cf1e202b36b94fae1f6411f1232ea4af1ad47ba31e54f2af1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/frr@sha256:6c47a60681d348a1cbfd5a497b74f612ad77969ae9e17a38d0eb60f68ed11315
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/frr@sha256:62c462b49459fc033c0cfc3816ff0eb2971edb8fbf6f6dcdeeeb19588d17bafa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/frr@sha256:4775321a4a2e82fba7c8434867c1579bf9f11db99ce231514544311b789d60e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/frr@sha256:419fa3a87ab80036dcb3b85938e83f863ce20553efcc943d542d550131448c2a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/frr@sha256:18faad6e36b08a31fb49060549509459321ebf83f471e6ca52e5628ca833ed56
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/frr@sha256:049a5fa4b34e7400d0567c68ff6a88ba2bc9e7419ab6ec9b1fcff29f46ea3f87
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/frr@sha256:352aad988fa44500a673daea9af6170242d1db61e77da27447d5480dc6102402
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/frr@sha256:2a1b4991b565dc166a4b1720fea5a54e46441a503956d813107cb088b17e0dd4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/frr@sha256:61e8462b119af43f2916f2e4396aa46dced8b668ad95bf4f19cf807320ec07b0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/frr@sha256:af3183bcab2528cc637f1c7feeb5d2e4c3dd6e1b5df9227d110b762b4e9173a5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/frr@sha256:253433a74db625824e027e56613745f398fdfa462d0258d812e10cecc0f06a8e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/frr@sha256:a7efe3ca56f8c67b42044adb90a320767b7077cd8a599c912b111c66de3290ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/frr@sha256:cb6cdc2c0cad1d6c6475b5dcac9fb4045989c7e9ea399f1dca4e88c6f5b031ab